Independent Security Process for File I/O Policy Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security programs for file input and output are complex and difficult to produce and update, requiring extensive professional effort and resources due to the need for multiple security control policies across different execution paths and formats, which complicates their implementation and maintenance.
Innovation Solution
A method and system where a security process runs independently of the main application program, connected to a filter driver that checks events and compares them against security control policies, allowing for centralized policy management and execution, thereby simplifying the production and update of security control policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple security control policies are implemented across different execution paths and formats, then security coverage is improved, but system complexity and production difficulty increase
Solution Approach 1:
The patent merges multiple security control policies into a single unified policy structure that can be executed across different paths. Instead of implementing separate policies for user-level and kernel-level operations, the invention creates one comprehensive security control policy that covers all execution paths, thereby reducing system complexity while maintaining comprehensive security coverage.
Solution Approach 2:
The security control policy is designed to be universal and multi-functional, capable of handling various security scenarios (file input, file output, directory operations, etc.) through a single policy framework. This universal policy can be applied across different execution contexts without requiring separate specialized policies for each scenario.
2Reliability
If multiple security control policies in different formats are maintained, then security control capability is improved, but ease of manufacture and update deteriorates
Solution Approach 1:
The patent enforces homogeneity by requiring all security control policies to be defined in a single standardized format (XML). This eliminates the need to maintain multiple policy formats, making policy creation, validation, and updates significantly easier while preserving comprehensive security control capability through the unified structure.
3Reliability
If comprehensive security control policies are implemented, then data security is improved, but resource consumption and cost increase
Solution Approach 1:
The patent extracts and isolates security control logic into a separate, dedicated security process that operates independently from the main application. This extraction allows the security subsystem to be optimized specifically for security operations, reducing overall resource consumption while maintaining comprehensive data security through dedicated security handling.
Data Source
AI summary
Provided herein is a method and system for the security of the file input and output of application programs. At a security process running step, an application program and an security process are executed independent of a main process of the application program. The security process is connected to a filter driver to control the filter driver. At an event generation step, the filter driver checks an event being processed by the application program, stops the processing of the event, and transfers event information regarding the event to the security process. At a control policy checking step, the security process compares the event information with a corresponding security control policy, and transfers the determination of the comparison to the filter driver. At an execution step, the filter driver continues the following processing of the corresponding event in conformity with the determination of the security process.


